At a Glance
- Tasks: Lead application security reviews and embed security in the Software Development Lifecycle.
- Company: Join a leading enterprise technology firm in the heart of London.
- Benefits: Competitive daily rate, hybrid working, and opportunities for contract extension.
- Other info: Immediate interview availability and excellent career growth potential.
- Why this job: Make a real impact on secure software development in a dynamic banking environment.
- Qualifications: 8+ years in Cyber Security with strong Application Security or DevSecOps experience.
The predicted salary is between 63000 - 77000 £ per year.
Location: London (Hybrid - 8 days onsite per month)
Contract: 12 Months + extension
Rate: £500-£550 per day (Umbrella)
The Opportunity
We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment. Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely. This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment.
Key Responsibilities
- Lead application security reviews across business-critical applications and cloud platforms.
- Conduct security architecture and secure design reviews.
- Perform application security risk assessments and define security requirements.
- Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies.
- Embed Secure SDLC principles into engineering teams.
- Integrate security tooling into CI/CD pipelines and DevSecOps processes.
- Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.
- Work closely with development teams to prioritise vulnerability remediation.
- Define security testing requirements and support penetration testing activities.
- Produce security standards, technical guidance and best practice documentation.
- Act as the Application Security SME across multiple technology programmes.
Essential Skills
- Application Security
- Secure Software Development Lifecycle (SSDLC)
- OWASP Top 10
- Secure Coding
- Secure Design Reviews
- API Security
- REST APIs
- Microservices Security
- Application Security Risk Assessments
- Threat Modelling
- STRIDE
- MITRE ATT&CK
- Security Architecture Risk Assessments
- DevSecOps
- CI/CD Security
- GitHub Actions
- GitLab
- Jenkins
- Azure DevOps
- Security Automation
- Shift Left Security
- Security Testing
- SAST
- DAST
- SCA
- Vulnerability Management
- Penetration Testing
- Cloud Security
- AWS, Azure or GCP
- Kubernetes
- Docker Container Security
- Cloud Security Best Practices
- Security Tooling
Experience with one or more of:
- Checkmarx
- Fortify
- SonarQube
- Veracode
- Semgrep
- Burp Suite
- OWASP ZAP
- Snyk
- Trivy
- Prisma Cloud
- Aqua Wiz
Ideal Background
- 8+ years in Cyber Security
- Strong Application Security or DevSecOps experience
- Experience working directly with software engineering teams
- Experience embedding security into CI/CD pipelines
- Strong knowledge of Secure SDLC
- Experience conducting Threat Modelling sessions
- Excellent stakeholder management and communication skills
- Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment
Contract Details
- 12-month contract
- £500-£600 per day (Umbrella)
- Hybrid working - 8 days onsite per month in London
- Immediate interview availability preferred
- Rates depend on experience and client requirements
Senior Application Security Consultant (SAST/DAST/OWASP ) in London employer: Salt
Join a forward-thinking investment management platform in London, where innovation meets opportunity. As a Senior Business Analyst, you'll thrive in a collaborative work culture that values your expertise and encourages professional growth through continuous learning and development. Enjoy the flexibility of a hybrid working model while contributing to cutting-edge AI-driven investment solutions that make a real impact in the financial services sector.